Naver
Products
17- 19 CVEs
- 8 CVEs
- 7 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- Billboard.js2 CVEsnpm
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
47| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-62583 | Cri | 0.64 | 9.8 | 0.00 | Oct 16, 2025 | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. | ||
| CVE-2025-53599 | Cri | 0.64 | 9.8 | 0.00 | Jul 4, 2025 | Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme. | ||
| CVE-2024-28212 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2024 | nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization. | ||
| CVE-2024-28211 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2024 | nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker. | ||
| CVE-2022-24074 | Cri | 0.64 | 9.8 | 0.01 | Mar 17, 2022 | Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises. | ||
| CVE-2021-33592 | Cri | 0.64 | 9.8 | 0.02 | Jul 19, 2021 | NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function. | ||
| CVE-2020-9752 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2020 | Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe. | ||
| CVE-2025-69234 | Cri | 0.59 | 9.1 | 0.00 | Dec 30, 2025 | Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment. | ||
| CVE-2020-9753 | Cri | 0.59 | 9.1 | 0.01 | May 20, 2020 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. | ||
| CVE-2020-9751 | Cri | 0.59 | 9.1 | 0.00 | Mar 3, 2020 | Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade. | ||
| CVE-2025-49223 | Cri | 0.57 | 9.8 | 0.01 | Jun 4, 2025 | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | ||
| CVE-2024-28213 | Cri | 0.57 | 9.8 | 0.01 | Mar 7, 2024 | nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization. | ||
| CVE-2021-33591 | Hig | 0.57 | 8.8 | 0.02 | May 28, 2021 | An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | ||
| CVE-2018-9859 | Hig | 0.53 | 8.1 | 0.01 | Jun 16, 2018 | The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications. | ||
| CVE-2026-8148 | Hig | 0.51 | 7.8 | 0.00 | May 8, 2026 | NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks. | ||
| CVE-2025-58322 | Hig | 0.51 | 7.8 | 0.00 | Aug 28, 2025 | NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improper privilege checks. | ||
| CVE-2022-24077 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2022 | Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection. | ||
| CVE-2018-12449 | Hig | 0.51 | 7.8 | 0.01 | Oct 11, 2018 | The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking. | ||
| CVE-2017-15913 | Hig | 0.51 | 7.8 | 0.01 | Jan 8, 2018 | The Installer in Whale allows DLL hijacking. | ||
| CVE-2025-58323 | Hig | 0.50 | 7.7 | 0.00 | Aug 29, 2025 | NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege checks. |
- risk 0.64cvss 9.8epss 0.00
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
- risk 0.64cvss 9.8epss 0.00
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.
- risk 0.64cvss 9.8epss 0.01
nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.
- risk 0.64cvss 9.8epss 0.01
nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.
- risk 0.64cvss 9.8epss 0.01
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
- risk 0.64cvss 9.8epss 0.02
NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function.
- risk 0.64cvss 9.8epss 0.01
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.
- risk 0.59cvss 9.1epss 0.00
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
- risk 0.59cvss 9.1epss 0.01
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
- risk 0.59cvss 9.1epss 0.00
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.
- risk 0.57cvss 9.8epss 0.01
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- risk 0.57cvss 9.8epss 0.01
nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
- risk 0.57cvss 8.8epss 0.02
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- risk 0.53cvss 8.1epss 0.01
The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications.
- risk 0.51cvss 7.8epss 0.00
NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.
- risk 0.51cvss 7.8epss 0.00
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improper privilege checks.
- risk 0.51cvss 7.8epss 0.00
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
- risk 0.51cvss 7.8epss 0.01
The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
- risk 0.51cvss 7.8epss 0.01
The Installer in Whale allows DLL hijacking.
- risk 0.50cvss 7.7epss 0.00
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege checks.